njRAT
MITRE ATT&CK: S0385 View on attack.mitre.org
Aliases: Njw0rm, LV, Bladabindi, Lime-Worm, njRAT
- First seen
- 2012-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 10777 (8816 malicious)
- Last IoC activity
- 2026-09-02 03:33:24
- Profile updated
- 2026-07-07 12:47:46
Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications
Targeted regions: country_code:ae country_code:sa country_code:eg
Context
njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.
Recent IoC activity
8,822 malicious indicators in Maltiverse are attributed to njRAT (S0385). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 3.64.4.198 | 2026-09-03 | 4 |
| IP address | 3.141.210.37 | 2026-09-03 | 6 |
| IP address | 213.152.187.220 | 2026-09-03 | 8 |
| IP address | 3.141.177.1 | 2026-09-03 | 6 |
| IP address | 3.127.253.86 | 2026-09-03 | 4 |
| IP address | 3.69.115.178 | 2026-09-03 | 4 |
| IP address | 3.68.171.119 | 2026-09-03 | 4 |
| IP address | 3.127.181.115 | 2026-09-03 | 4 |
| IP address | 3.125.188.168 | 2026-09-03 | 4 |
| IP address | 3.126.224.214 | 2026-09-03 | 4 |
| file sample | de7ce0b4b98abcfcaa736f28f3abce6a4ecc4dc5083bac5c1ef3d3b821618925.exe | 2026-09-03 | 2 |
| hostname | comes-corruption.at.ply.gg | 2026-09-03 | 1 |
| hostname | mohamednjrat111.no-ip.biz | 2026-09-03 | 1 |
| hostname | chromeupdate.servepics.com | 2026-09-03 | 3 |
| hostname | teste2018.ddns.net | 2026-09-03 | 1 |
| hostname | teaching-wireless.gl.at.ply.gg | 2026-09-03 | 1 |
| hostname | jinmo0721.kro.kr | 2026-09-03 | 1 |
| hostname | dolaaultra.no-ip.biz | 2026-09-03 | 1 |
| hostname | indigo2forjoy.com | 2026-09-03 | 1 |
| hostname | hours-morrison.gl.at.ply.gg | 2026-09-03 | 1 |
Detection coverage
- 9 YARA rules
- 637 Sigma rules
Malware & tools used
- Credentials from Web Browsers (attack-pattern)
- Application Window Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Query Registry (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Video Capture (attack-pattern)
- Screen Capture (attack-pattern)
- Native API (attack-pattern)
- Remote System Discovery (attack-pattern)
- File Deletion (attack-pattern)
- PowerShell (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Standard Encoding (attack-pattern)
- Compile After Delivery (attack-pattern)
- Non-Standard Port (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Keylogging (attack-pattern)
- Web Protocols (attack-pattern)
- Windows Host Firewall (attack-pattern)
- Clear Persistence (attack-pattern)
- Modify Registry (attack-pattern)
Used by threat actors
- Operation Spalax (campaign)
- Gorgon Group (threat-actor)
- Aquatic Panda (threat-actor)
- Transparent Tribe (threat-actor)
- APT-C-36 (threat-actor)
- APT41 (threat-actor)
- LazyScripter (threat-actor)
- Group5 (threat-actor)
- TA2541 (threat-actor)
Detection rules
- SECUINFRA_DROPPER_Njrat_VBS (yara-rule)
- SECUINFRA_MAL_Njrat (yara-rule)
- EMBEERESEARCH_Win_Njrat_Strings_Oct_2023 (yara-rule)
- EMBEERESEARCH_Win_Njrat_Bytecodes_V2_Oct_2023 (yara-rule)
- EMBEERESEARCH_Win_Njrat_Bytecodes_Oct_2023 (yara-rule)
- DITEKSHEN_MALWARE_Win_Cobianrat (yara-rule)
- SEKOIA_Crimeware_Njrat_Strings (yara-rule)
- SIGNATURE_BASE_HKTL_NET_NAME_RAT_Njrat_0_7D_Modded_Source_Code (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_Njrat (yara-rule)
Related threat objects
- Kiler RAT (malware)
Reports & references
- secureworks.com — Copper Fieldstone (report)
- vectra.ai — Moonlight Middle East Targeted Attacks (report)
- ecucert.gob.ec — Alerta Apts 2022 03 23 (report)
- ti.360.net — Analysis Of Apt C 27 (report)
- MITRE ATT&CK — G0096 (report)
- Cisco Talos — Sidecopy (report)
- Kaspersky — 91897 (report)
- researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
- ESET — Eset Threat Report Q22020 (report)
- bleepingcomputer.com — Fake Microsoft Teams Updates Lead To Cobalt Strike Deployment (report)
- intel471.com — Privateloader Malware (report)
- intezer.com — Intezer 2020 Go Malware Round Up (report)
- s3.amazonaws.com — 062521 Sidecopy %281%29 (report)
- s3.amazonaws.com — 062521 Sidecopy %281%29 (report)
- s3.amazonaws.com — Hashes Iocs For Coverage.Txt (report)
- s3.amazonaws.com — Network Iocs List For Coverage.Txt (report)
- intel471.com — China Cybercrime Undergrond Deepmix Tea Horse Road Great Firewall (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)